Skip to content

Bind v0.2.2 evidence to the tested runtime - #72

Merged
AetherAI3 merged 1 commit into
mainfrom
docs/release-evidence-0.2.2
Sep 4, 2026
Merged

Bind v0.2.2 evidence to the tested runtime#72
AetherAI3 merged 1 commit into
mainfrom
docs/release-evidence-0.2.2

Conversation

@AetherAI3

Copy link
Copy Markdown
Owner

Binds the v0.2.2 release record to runtime commit 648269bf4ec5da534f2a4afe81104ab52c826bb3 and hosted release-evidence run 33865946626.

Every figure was re-derived from that run's own artifacts rather than carried over from the v0.2.1 record:

  • sbom.spdx.json de35b206… (630 packages, Syft 1.51.1) and vulnerabilities.json 1b6777d1… (Grype 0.118.0) — both SHA-256s recomputed from the downloaded artifacts.
  • Image ID sha256:4df5d324…, base digest unchanged at the pinned python:3.11-slim-bookworm digest.
  • acceptance.json = PASS over 33 checks at that image ID; quickstart.json = PASS.
  • Chrome 152.0.7977.82 / google-chrome-stable 152.0.7977.82-1 / amd64; notices bundle hash unchanged.
  • Strict gate at the runtime commit: 14 PASS, 2 SKIP, 1 FAIL — the single failure is exact-commit-evidence, which is the pointer this commit moves. version-agreement reads 0.2.2 across project, package, Compose, and image label.
  • Vulnerability posture re-counted from this run's vulnerabilities.json: an empty matches set and 917 ignoredMatches (12 fixed, 570 not-fixed, 330 wont-fix, 5 no state; 42 critical, 198 high, 289 medium, 57 low, 290 negligible, 41 unknown). Identical to 0.2.1 because the base digest, the hash-locked environment, and the Chrome package are all pinned — the wording now says that explicitly, and that the counts come from ignoredMatches rather than matches.

The Status paragraph now describes what 0.2.2 actually is: the MCP Registry publication surface, no runtime change.

Changes only docs/RELEASE_EVIDENCE.md, within the evidence allowlist. Verified locally: the runtime commit is an ancestor of this branch, git diff --name-only <runtime>..HEAD returns that one path, and no pending-evidence markers remain.

@AetherAI3
AetherAI3 merged commit 85ec2a6 into main Sep 4, 2026
10 checks passed
@AetherAI3
AetherAI3 deleted the docs/release-evidence-0.2.2 branch September 4, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant